arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

TI-StegoAlign:面向分词不一致场景的生成式文本隐写的通道导向后训练方法

TI-StegoAlign: Channel-Guided Post-Training for Generative Text Steganography under Tokenization Inconsistency

Jiuan Zhou, Yuhao Xue, Yu Cheng, Yuan Xie, Zhaoxia Yin

arXiv 2608.00382首次发表:更新:

AI 中文总结

TI-StegoAlign是一种仅更新LoRA参数的通道导向后训练框架,通过BCSO和CCPO优化,在分词不一致场景下实现100%接收方比特准确率,同时降低归一化困惑度偏差并提升抗隐写分析性能。

AI 中文摘要

生成式文本隐写使大语言模型(LLM)智能体能够通过与任务相关的消息交换秘密信息。然而,大多数方法在发送方侧的分词上评估恢复效果,而接收方仅能观察到表面文本。去分词和接收方侧的重新分词会改变分词边界、使编码状态不同步,导致此类评估高估接收方侧的恢复效果。现有补救措施依赖推理时的过滤或验证,仅校正单个输出,未使生成策略适配接收方侧通道。为解决这些局限,我们提出TI-StegoAlign,一种通道导向后训练框架。位一致性监督目标(BCSO)在已实现的发送方侧嵌入位置处扩大局部编码裕度;通道条件偏好优化(CCPO)随后利用接收方真实恢复效果、文本质量及抗隐写分析反馈对齐完整隐写文本。TI-StegoAlign仅更新LoRA参数,通信期间无需特定分词校正。实验结果显示,其接收方比特准确率达100%;与最强基线相比,TI-StegoAlign使归一化困惑度偏差降低21.6%,抗隐写分析性能相对提升6.3%。

英文摘要

Generative text steganography enables LLM agents to exchange secret information through task-relevant messages. Yet most methods evaluate recovery on sender-side tokens, whereas the receiver observes only surface text. Detokenization and receiver-side retokenization can alter token boundaries, desynchronize coding states, and cause such evaluation to overestimate receiver-side recovery. Existing remedies rely on inference-time filtering or verification, correcting individual outputs without adapting the generation policy to the receiver-side channel. To address these limitations, we propose TI-StegoAlign, a channel-guided post-training framework. The Bit-Consistent Supervised Objective (BCSO) enlarges local coding margins at realized sender-side embedding positions. Channel-Conditioned Preference Optimization (CCPO) then aligns complete stegotexts using receiver-realistic recovery, text quality, and anti-steganalysis feedback. TI-StegoAlign updates only LoRA parameters and requires no tokenization-specific correction during communication. Experimental results show 100% receiver bit accuracy. Compared with the strongest baselines, TI-StegoAlign achieves a 21.6% reduction in normalized perplexity deviation and a 6.3% relative improvement in anti-steganalysis performance.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑